Scrut Automation
The only GRC platform I have audited that is itself ISO 42001 certified, processes AI personal data in Frankfurt under its own DPA, and built its MCP so an agent structurally cannot delete your compliance records. Nine named agents do real work. The hole in the middle is that after three years Scrut still will not name the models running any of it.
PRICING
| Compliance Automation (AWS Marketplace) | $15,000 per 12-month contract | the only published price point; covers organisations up to 20 employees |
| Small team, quote | Quote only | reported $15,000-$20,000/yr, all frameworks and modules bundled |
| Mid-market, quote | Quote only | reported $18,000-$30,000/yr for two or more frameworks |
| Enterprise, quote | Quote only | reported $40,000-$50,000+/yr for five or more frameworks and multi-entity scope |
Bundling is the whole commercial argument and it holds for multi-framework teams: independent analysis puts SOC 2 plus ISO 27001 at roughly $22,000 on Scrut against roughly $28,000 on Drata, and reports renewal pricing as steadier than the year-two jumps common elsewhere. For a lean startup chasing one certification the advantage largely disappears, since $15,000-$20,000 is comparable to the competition's entry tier. Multi-year commitments reportedly attract 10-25% discounts.
checked 2026-08-13 · vendor pricing page
Element scores
Strengths
Scrut is the only vendor in this category I have audited that holds ISO/IEC 42001:2023 for its own AI management system, certified in January 2025 with StackAware. That is a third-party audit of how it governs AI, not a page describing good intentions, and it sits alongside a firm commitment never to use customer data to train models for other customers and AI features that are opt-in per feature rather than on by default. For European buyers there is a second, sharper point: the Data Protection Addendum commits to processing personal data with AI and machine learning inside the Frankfurt region in Germany under GDPR, which is a contractual data residency guarantee for the AI layer that the American leaders do not currently match. The agent layer is the most developed of the three GRC platforms audited so far: nine named Teammates with real separation of duties, including a Security Analyst that runs agent-driven penetration testing end to end with human verification of every finding, and a Vendor Risk Analyst that discovers shadow AI, sends tailored questionnaires and monitors breaches continuously. Two design decisions deserve specific credit. The questionnaire agent flags gaps and says when it is not confident rather than producing a plausible answer, and MCP write actions are additive by construction — an assistant can upload and attach evidence but structurally cannot delete or overwrite a compliance record. Commercially the flat bundle is genuinely different: every framework, module and seat in one subscription, which independent analysis puts at roughly $6,000 a year cheaper than Drata for a SOC 2 plus ISO 27001 programme.
Honest dings
For a company selling AI transparency as its differentiator, Scrut will not say what it runs. The only model disclosure anywhere is a 2023 launch note naming OpenAI; the current AI security page discusses fairness and accountability at length and never names a model, a provider or a version. 'Post-trained on real-world scenarios' and 'tenant-specific AI' are adaptation claims with no published mechanism behind either. There is no eval surface you can run, no published accuracy figure, and the only number in circulation is a customer testimonial. The MCP is real but early: thirteen tools against the leaders' hundred-plus, and read-heavy. The integration library at 150+ is materially smaller than Vanta's 400+ or Secureframe's 300+, which is a genuine risk if your stack has anything unusual in it. Independent reviewers consistently flag three operational issues: agent sync delays where device configuration changes do not appear promptly, a steep learning curve for teams new to GRC, and support running on India time zones, which US buyers on a deadline should test during the sales process. Pricing is quote-only with no free trial, and company location is reported inconsistently across sources — Bengaluru, Milpitas, Palo Alto and San Francisco all appear, which matters if your procurement needs a definitive contracting entity.
Sources (16) — every claim traceable
Every audit lists the research it rests on — transparency and traceability are the product. Tools evolve: each audit is a snapshot of its audit date, and re-audits supersede older versions (kept below for reference).
- scrut.io — Official homepage: 2,500+ customers, 4.9/5 across 1,300+ reviews, 10M+ assets monitored, 70+ frameworks, 150+ integrations, the nine named Scrut Teammates with their stated scope, and the MCP summary of 10 tools with OAuth and multi-region (accessed 2026-08-13)
- scrut.io/post/meet-scrut-mcp — Official 20/07/2026 launch: full table of 13 MCP tool names and what each does, four packaged skills (compliance digest, answer questionnaire, upload evidence, fix test), per-user OAuth permission inheritance, the statement that write actions are additive and cannot delete or overwrite, audit logging of MCP-filed evidence, and that scrut_answer_question flags gaps rather than guessing when unconfident (accessed 2026-08-13)
- scrut.io/platform/scrut-teammates — Official product page: 2,500+ customers and 850+ teams using Teammates, claimed 800+ hours saved on vendor risk and 2 days per questionnaire, the proprietary knowledge graph and 'System of Agents' architecture, post-training by in-house security experts, and the four AI trust claims (ISO 42001 certified, opt-in, audited workflows, non-training) (accessed 2026-08-13)
- scrut.io/scrut-ai — Official AI security page: opt-in features, data never used to train external models or models for other customers, isolated per-tenant processing, retention and deletion options, regular AI module reviews at major releases, third-party audits, and the three stated tenets of tenant-specific AI, privacy-preserving automation and security-first applications. Names no model, provider or version. (accessed 2026-08-13)
- scrut.io/post/scrut-achieves-iso-42001-certificatio… — Official 05/02/2025: ISO/IEC 42001:2023 certification achieved January 2025, among the first GRC platforms to do so, with CEO Aayush Ghosh Choudhury and CISO Nick Muy quoted, and the four-step process Scrut followed (accessed 2026-08-13)
- scrut.io/dpa — Official Data Protection Addendum: personal data processed using AI and machine learning technologies within the Frankfurt region, Germany, in accordance with GDPR and limited to what is necessary for the service; compliance with ISO/IEC 27001:2022 and ISO 27701:2019 (accessed 2026-08-13)
- scrut.launchnotes.io/announcements/ann_UWJ1M9Qf6YZPl — Official product update 03/08/2023 launching ScrutGPT: the only disclosure found stating the questionnaire feature leverages LLMs and OpenAI. Three years old and not reconfirmed anywhere current. (accessed 2026-08-13)
- scrut.io/integrations — Official integration catalogue across compliance, identity, data, dev and cloud, project management, support, sales, security and IT, and HRMS, with a request form for anything missing (accessed 2026-08-13)
- aws.amazon.com/marketplace/pp/prodview-fz4mb7o7dzj4i — Marketplace listing: the only published Scrut price, $15,000 for a 12-month Compliance Automation contract covering organisations up to 20 employees, plus a June 2026 G2-sourced customer review on automated evidence collection (accessed 2026-08-13)
- blog.stackaware.com/p/automation-iso-42001-ai-gover… — Independent (StackAware, the partner firm): the ISO 42001 partnership announced August 2024 with formal certification in January 2025, and the AI risk assessment API used to accelerate it (accessed 2026-08-13)
- soc2auditors.org/insights/scrut-review — Independent 30/05/2026: bundled pricing saving $5,000-$12,000/yr against Vanta or Drata, SOC 2 plus ISO 27001 at ~$22,000 versus ~$28,000 on Drata, $15,000-$40,000 quote bands, $1,000-$5,000 onboarding fee, G2 4.8-4.9 across ~180 reviews, ~1,400-1,500 pre-mapped controls and 400+ automated tests, integration library smaller than peers, steeper learning curve, and India-timezone support flagged for US teams (accessed 2026-08-13)
- compliancerated.com/tools/scrut-automation/pricing — Independent: flat-rate not per-seat pricing with all 60+ frameworks bundled, $15,000-$20,000 for under 50 employees rising to $40,000+ for five or more frameworks, 10-25% multi-year discounts, G2 4.9 across 1,298 reviews, and Scrut Agent sync delays named as the most frequent technical complaint alongside the learning curve (accessed 2026-08-13)
- soc2auditors.org/software/scrut — Independent software record 24/07/2026: ~$20.5M total funding since the 2021 founding including a $10M growth round April 2024 from Lightspeed, MassMutual Ventures and Endiya Partners; founders Aayush Ghosh Choudhury, Kush Kaushik and Jayesh Gadewar; no published pricing page; conflicting HQ reporting across Forbes (San Francisco) and Crunchbase (Bangalore) (accessed 2026-08-13)
- smartsuite.com/blog/scrut-automation-pricing — Independent but competitor-authored (treat directionally) 25/03/2026: confirms the AWS Marketplace $15,000 floor, estimates $18,000-$30,000 mid-market and $40,000-$50,000+ enterprise, notes no free plan or trial, and quotes G2 reviews on cluttered multi-framework UI, template rigidity and one negative review citing time-zone-incompatible collaboration (accessed 2026-08-13)
- cbinsights.com/company/scrut-automation — Independent company record: $20.5M raised, Series A stage, Milpitas California address on file with India operations, and the G2 2026 Best Software Awards placement at #9 for GRC products (accessed 2026-08-13)
- scrut.io/integrations/openai — Official: Scrut's OpenAI integration is for governing your team's GenAI usage — access reviews, account deprovisioning on offboarding, usage oversight — not a disclosure of what Scrut itself runs. Worth separating, since the two are easily confused. (accessed 2026-08-13)